skills/adryanmoldokkr32-pixel/bionicbot-giant-sovereign-skills/legal-sovereignty-engine/Gen Agent Trust Hub
legal-sovereignty-engine
Pass
Audited by Gen Agent Trust Hub on Apr 19, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its requirement to monitor external, untrusted data sources.
- Ingestion points: Monitoring external changes in 'Tax Havens' and 'Privacy Jurisdictions' (SKILL.md).
- Boundary markers: None present. The agent is not instructed to distinguish between legitimate legal updates and potentially malicious instructions embedded in those updates.
- Capability inventory: Drafting legal paperwork, managing entities, and responding to bank/exchange requests.
- Sanitization: No sanitization or validation of the monitored external data is specified.
- [DATA_EXFILTRATION]: The instruction to 'Automate the KYC/AML responses' (SKILL.md) requires the agent to handle and transmit highly sensitive Personally Identifiable Information (PII) and financial records to external domains (bank and exchange APIs or portals). This creates a risk surface where sensitive data could be misdirected or exposed during the automated response process.
- [NO_CODE]: The skill contains only natural language instructions and YAML metadata. No scripts, binaries, or configuration files that execute code were found.
Audit Metadata